Here are some Windows 10 CLI / Powershell commands I use once in a while. Using this as my personal notepad, so to speak; might be useful for someone.
reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge /v DefaultBrowserSettingEnabled /t REG_DWORD /d 0 /f
reg add HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge /v DefaultBrowserSettingsCampaignEnabled /t REG_DWORD /d 0 /f
This is a fairly long list. I run these normally after a fresh Windows install. You can copy / paste this into an admin-Powershell window. All at once, or individually of course. Or, save as a .ps1 file and execute. See here: --> https://gist.github.com/jonkeren/537dba7f7cf84e319c634f7e9af4f2f8
Windows Explorer can be really slow if the folder has a lot of files. Can be solved with:
reg.exe add "HKEY_CURRENT_USER\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell" /v "FolderType" /t REG_SZ /d "NotSpecified" /f
On Windows 11 Onedrive is very slow accessing through the main window Onedrive or SharePointsync'd folders. Using procmon, Explorer.exe is losing 5-6 seconds doing a lot of ReqQueryKey on the HKCU\Software\Classes\ tree. It boils down on changing permission to full control for the ondrivesync entries here: Computer\HKEY_CLASSES_ROOT\PackagedCom\Package\Microsoft.OneDriveSync_xxxxxxxx to the "Everyone" account. No more entries logged on HKCU\Software\Classes tree. This speeds up Navigating Onedrive folders in Explorer by at least 10x. This script sets the rights on those registry keys, for all keys starting with Microsoft.OneDriveSync_.
Also after a reboot it persists. You maybe should run this again after a new version of OneDrive is installed, and a new key (with another version number) is created.
Script here: --> https://github.com/jonkeren/windows-10-commands/blob/master/Fix-OneDrive-Speed-Using-Registry.ps1
This is for my pc driver setup currently. You may have different services.
REM Intel Content Protection HECI Service (Handles DRM and digital content protection for Intel graphics)
sc config "cplspcon" start= disabled
sc stop "cplspcon"
REM Intel HD Graphics Control Panel Service (Manages the Intel Graphics UI, custom resolutions, and hotkeys)
sc config "igfxCUIService2.0.0.0" start= disabled
sc stop "igfxCUIService2.0.0.0"
REM Intel Graphics Software Service (Background service for the modern Intel Graphics Command Center)
sc config "IntelGraphicsSoftwareService" start= disabled
sc stop "IntelGraphicsSoftwareService"
REM Intel PIE Service (Product Improvement Experience - handles Intel telemetry and data collection)
sc config "PIEServiceNew" start= disabled
sc stop "PIEServiceNew"
REM Killer Analytics Service (Collects telemetry and usage analytics for Killer/Intel networking cards)
sc config "Killer Analytics Service" start= disabled
sc stop "Killer Analytics Service"
REM Killer Network Dynamic Bandwidth Manager (Manages network traffic prioritization for gaming/streaming)
sc config "KNDBWM" start= disabled
sc stop "KNDBWM"
REM Killer Network Service (Core background service for Killer networking features and the Control Center)
sc config "Killer Network Service" start= disabled
sc stop "Killer Network Service"
REM Killer Provider Data Helper Service (Helper service that gathers network metrics for the Killer Control Center)
sc config "Killer Provider Data Helper Service" start= disabled
sc stop "Killer Provider Data Helper Service"
REM Killer AP Selection Service (Manages Smart Wi-Fi access point routing and selection for Killer cards)
sc config "KAPSService" start= disabled
sc stop "KAPSService"
REM NVIDIA Display Container LS (Core background service required for NVIDIA display drivers and Control Panel)
sc config "NVDisplay.ContainerLocalSystem" start= disabled
sc stop "NVDisplay.ContainerLocalSystem"
REM Intel Audio Service (Manages Intel Smart Sound Technology and audio enhancements)
sc config "IntelAudioService" start= disabled
sc stop "IntelAudioService"
start ms-windows-store://pdp/?ProductId=9n4wgh0z6vhq
POWERCFG -SETDCVALUEINDEX SCHEME_CURRENT SUB_NONE CONNECTIVITYINSTANDBY 0
POWERCFG -SETACVALUEINDEX SCHEME_CURRENT SUB_NONE CONNECTIVITYINSTANDBY 0
irm https://get.activated.win | iex
See: https://github.com/massgravel/Microsoft-Activation-Scripts
reg add HKLM\System\CurrentControlSet\Control\Power /v PlatformAoAcOverride /t REG_DWORD /d 0
reg add HKLM\System\CurrentControlSet\Control\Power /v CsEnabled /t REG_DWORD /d 0
reg add HKLM\System\CurrentControlSet\Control\Power /v EnforceDisconnectedStandby /t REG_DWORD /d 0
POWERCFG /SETACVALUEINDEX 381b4222-f694-41f0-9685-ff5bb260df2e SUB_NONE CONNECTIVITYINSTANDBY 0
POWERCFG /SETDCVALUEINDEX 381b4222-f694-41f0-9685-ff5bb260df2e SUB_NONE CONNECTIVITYINSTANDBY 0
Go to Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB\VID_8087&PID_0026\5&3b777946&0&14\Device Parameters.
Device name and numer might be different. In this case the device name is "Intel(R) Wireless Bluetooth(R)".
Add 3 key/values:
"DeviceSelectiveSuspended"=dword:00000000
"SelectiveSuspendEnabled"=dword:00000000
"SelectiveSuspendSupported"=dword:00000000
- https://github.com/AveYo/LeanAndMean/blob/main/ToggleDefender.bat
- https://www.sordum.org/9480/defender-control-v2-1/
Get-AppXPackage | Out-GridView -Passthru | Remove-AppXPackage
Get-AppXPackage -AllUsers | Out-GridView -Passthru | Remove-AppXPackage
Get-AppxProvisionedPackage -Online | Out-GridView -PassThru | Remove-AppxProvisionedPackage -Online
Set-ExecutionPolicy Bypass -Scope Process -Force; [System.Net.ServicePointManager]::SecurityProtocol = [System.Net.ServicePointManager]::SecurityProtocol -bor 3072; iex ((New-Object System.Net.WebClient).DownloadString('https://vcredist.com/install.ps1'))
rundll32.exe pnpclean.dll,RunDLL_PnpClean /DRIVERS /MAXCLEAN
sc stop “wsearch” && sc config “wsearch” start=disabled
sc config “wsearch” start=delayed-auto && sc start “wsearch”
sfc /scannow
Dism.exe /Online /Cleanup-Image /CheckHealth
DISM.exe /Online /Cleanup-Image /ScanHealth
Dism.exe /Online /Cleanup-Image /RestoreHealth
Dism.exe /Online /Cleanup-Image /AnalyzeComponentStore
Dism.exe /online /Cleanup-Image /StartComponentCleanup
Dism.exe /online /Cleanup-Image /StartComponentCleanup /ResetBase
Dism.exe /online /Cleanup-Image /SPSuperseded
sfc /scannow
$DesktopPath = [Environment]::GetFolderPath("Desktop");
mkdir "$DesktopPath\GodMode.{ED7BA470-8E54-465E-825C-99712043E01C}"
$jos = "HKLM\SYSTEM\CurrentControlSet\Control\Power\PowerSettings"
$querylist = reg query $jos
foreach ($regfolder in $querylist){
$querylist2 = reg query $regfolder
foreach($2ndfolder in $querylist2){
$active2 = $2ndfolder -replace "HKEY_LOCAL_MACHINE" , "HKLM:"
Get-ItemProperty -Path $active2
Set-ItemProperty -Path "$active2" -Name "Attributes" -Value '2'
}
$active = $regfolder -replace "HKEY_LOCAL_MACHINE" , "HKLM:"
Get-ItemProperty -Path $active
Set-ItemProperty -Path "$active" -Name "Attributes" -Value '2'
}
REG ADD "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Store" /v StoreContentModifier /f /t REG_SZ /d DELL_Xps
This disables the Windows Update scheduled tasks, takes ownershop of the UpdateOrchestrator dir, disables startup of wuauserv and set it to disabled.
$WindowsUpdatePath = "HKLM:SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\"
$AutoUpdatePath = "HKLM:SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU"
Set-ItemProperty -Path $AutoUpdatePath -Name NoAutoUpdate -Value 1
Get-ScheduledTask -TaskPath "\Microsoft\Windows\WindowsUpdate\" | Disable-ScheduledTask
Set-Service UsoSvc -StartupType Disabled -PassThru | Stop-Service
Set-ItemProperty -Path "HKLM:SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" -Name NoAutoUpdate -Value 1
Set-ItemProperty -Path "HKLM:SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU" -Name AUOptions -Value 2
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\WaaSMedicSvc\" -Name Start -Value 4
takeown /F C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator /A /R
icacls C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator /grant Administrators:F /T
Get-ScheduledTask -TaskPath "\Microsoft\Windows\UpdateOrchestrator\" | Disable-ScheduledTask
Set-Service wuauserv -StartupType Disabled
sc.exe config wuauserv start=disabled
Stop-Service wuauserv
sc.exe stop wuauserv
takeown /f c:\windows\system32\WaaSMedicSvc.dll
$pause = (Get-Date).AddDays(365); $pause = $pause.ToUniversalTime().ToString( "yyyy-MM-ddTHH:mm:ssZ" ); Set-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings' -Name 'PauseUpdatesExpiryTime' -Value $pause
Powershell create directories based on file extensions; and move the files to their extension directory. (This sorts files in one large directory into multiple subdirectories).
Get-ChildItem -File | % { Process { $_.Extension }} | Select -Unique | % { Process { New-Item $_ -ItemType Directory -Force }};
Get-ChildItem -File | % { Process { Move-Item $_ -Destination $_.Extension -Force }};
Powershell list status of all devices that have the option "Power Management - Allow the computer to turn off this device to save power"
Get-CimInstance -ClassName MSPower_DeviceEnable -Namespace root/WMI
Powershell automatically enable "Power Management - Allow the computer to turn off this device to save power" (set check box) for all devices
Get-CimInstance -ClassName MSPower_DeviceEnable -Namespace root/WMI | Set-CimInstance -Property @{Enable = $true}
Powershell automatically disable "Power Management - Allow the computer to turn off this device to save power" (uncheck box) for all devices
Get-CimInstance -ClassName MSPower_DeviceEnable -Namespace root/WMI | Set-CimInstance -Property @{Enable = $false}
@echo off
setlocal
for %%I in (*.pdf) do (
gswin64c.exe -dNOPAUSE -dBATCH -dNumRenderingThreads=4 -sDEVICE=jpeg -r300 -dJPEGQ=80 -dFirstPage=1 -dLastPage=1 -sOutputFile="%%~nI_p%%02d.jpg" "%%~I"
)
gci -recurse . | where {$_.Name -match "[^\u0000-\u00FF]"} | select -expand FullName
Get-ChildItem -Recurse | where {$_.Name -match "\u2019"} | Rename-Item -NewName { $_.Name -Replace "\u2019","'" } -Passthru
Powershell recursively remove some files (also hidden and system) from subdirectories:
Get-ChildItem -File -Include *.DS_Store -Recurse -Force | Remove-Item -Force -Verbose
attrib +p -u /s /d
attrib -p +u /s /d
Get-ChildItem -Recurse -Force . | where { $_.PSISContainer -and @( $_ | Get-ChildItem ).Count -eq 0 } | Remove-Item -Verbose -Force
Powershell rename all jpg images and videos, to strip the "IMG_" and "VID_" prefix, and to replace underscores with dashes:
Get-ChildItem -Recurse 'IMG_20*.*' | Rename-Item -NewName { $_.Name -Replace 'IMG_20','20' } -Passthru
Get-ChildItem -Recurse 'VID_20*.*' | Rename-Item -NewName { $_.Name -Replace 'VID_20','20' } -Passthru
Get-ChildItem -Recurse '20??????_*.*' | Rename-Item -NewName { $_.Name -Replace '_','-' } -PassThru
taskkill /F /IM <NAME>.exe /T
Get-WinEvent -ListLog * | where {$_.RecordCount} | ForEach-Object -Process { [System.Diagnostics.Eventing.Reader.EventLogSession]::GlobalSession.ClearLog($_.LogName) }
for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1"
for %i in (*.opus) do ffmpeg -i "%i" -q:a 2 "%~ni.mp3"
Powershell move files to date-based subdirectories, based on the first characters (date) of the file name
This moves files names like 20251016-blabla.mp3 to a subfolder 2025\10\16.
$Source = 'SOURCE FOLDER'
GEt-ChildItem $Source *.mp3 | ForEach{
$Destination = ($_.Name.Substring(0,4)),($_.Name.Substring(4,2)),($_.Name.Substring(6,2)) -join '\'
If ( -not ( Test-Path $Destination )) {
mkdir $Destination | out-null
}
Move-Item $_.FullName $Destination
echo $Destination $_.FullName
}
This will recurse the directory, and automatically add an incoming and outgoing block rule in the Windows Firewall to block all program's access to internet.
Get-ChildItem -Recurse -Path "C:\Program Files\Adobe" *.exe |
Select-Object Name,FullName |
ForEach-Object `
{New-NetFirewallRule -DisplayName "Block $($_.Name) Inbound" -Direction Inbound -Program "$($_.FullName)" -Action Block;
New-NetFirewallRule -DisplayName "Block $($_.Name) Outbound" -Direction Outbound -Program "$($_.FullName)" -Action Block}
Get-ChildItem -Recurse -Path "C:\Program Files (x86)\Adobe" *.exe |
Select-Object Name,FullName |
ForEach-Object `
{New-NetFirewallRule -DisplayName "Block $($_.Name) Inbound" -Direction Inbound -Program "$($_.FullName)" -Action Block;
New-NetFirewallRule -DisplayName "Block $($_.Name) Outbound" -Direction Outbound -Program "$($_.FullName)" -Action Block}
Get-ChildItem -Recurse -Path "C:\Program Files\Common Files\Adobe" *.exe |
Select-Object Name,FullName |
ForEach-Object `
{New-NetFirewallRule -DisplayName "Block $($_.Name) Inbound" -Direction Inbound -Program "$($_.FullName)" -Action Block;
New-NetFirewallRule -DisplayName "Block $($_.Name) Outbound" -Direction Outbound -Program "$($_.FullName)" -Action Block}
Get-ChildItem -Recurse -Path "C:\Program Files (x86)\Common Files\Adobe" *.exe |
Select-Object Name,FullName |
ForEach-Object `
{New-NetFirewallRule -DisplayName "Block $($_.Name) Inbound" -Direction Inbound -Program "$($_.FullName)" -Action Block;
New-NetFirewallRule -DisplayName "Block $($_.Name) Outbound" -Direction Outbound -Program "$($_.FullName)" -Action Block}
Run this to rename these 5 exe-files.
move "C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe" "C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe.jos"
move "C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe" "C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe.jos"
move "C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" "C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe.jos"
move "C:\Program Files\Common Files\Adobe\Creative Cloud Libraries\CCLibrary.exe" "C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe.jos"
move "C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe" "C:\Program Files\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe.jos"